basalt / http/src / GUARDED_META_KEYS
Variable: GUARDED_META_KEYS
> const GUARDED_META_KEYS: readonly ["auth", "mfa", "can", "teamRole", "scopes", "subscribed", "feature"]
Defined in: http/src/guarded-meta.ts:24
The security-relevant route-meta keys the framework knows about. Each is enforced by a guard that a specific plugin registers:
auth,mfa—@basaltkit/auth'sauthPlugincan—@basaltkit/permissions'permissionsPluginteamRole—@basaltkit/teams'teamsPluginscopes—@basaltkit/auth'sapiKeysPluginsubscribed,feature—@basaltkit/subscriptions'subscriptionsPlugin
Declaring one of these on a route is a request for protection; the guard is what enforces it. A route that declares a key nobody enforces would silently serve unprotected — the adapters therefore call assertRoutesGuarded at boot and fail loud instead.
Deliberately NOT in this set: central (a tenant-membership opt-out — a missing plugin removes a bypass, never a check), mcp (an exposure opt-in) and rateLimit (abuse throttling, not an authorization boundary, and legal to declare with securityPlugin's optional rate limiter switched off).